本帖最后由 xmzhqw 于 2022-11-3 08:41 编辑
(9)用Regshot 捕捉注册表信息变化,获得自己想要的注册码。求人不如求自己!
不少注册表都可以用捕捉的方法来得到。很多时候求人不如求自己。捕捉注册表变化的软件有不少,我觉得还是Regshot好用。使用方法:
还是举个例子吧:比如在本帖的回复中,有坛友想达到这样的效果(看图)
而在PE中,想要达到这样的效果,只要点击方框内的三角形,选择自己要的功能即可达到。那我们要怎样获得这种效果的注册码呢?
第一步:进入PE后,关掉你能关掉的所有进程,打开Regshot,点击“建立快照(A)”。
第二步:随便打开一个文件夹,在资源管理器中完成你要的效果设置,即如下图所示,把你想要的打勾或去勾;
第三步:设置完成后,关闭资源管理器,点击“建立快照(B)”,系统会自动生成一个文件夹X:\Hive,
打开report.1.Undo.reg 或report.1.Redo.reg ,你很快就可以找到捕捉到的注册码(下图框内) (10)★去除win11资源管理器中的主文件夹 ★★★ 方法一:导入下面的注册码:(无垠老大提供)用了以后还没发现什么后遗症,推荐使用。 - Windows Registry EditorVersion 5.00
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer]
- "hubmode"=dword:00000001
复制代码- Windows Registry EditorVersion 5.00
- [HKEY_LOCAL_MACHINE\pe_soft\Classes\CLSID\{f874310e-b6b7-47dc-bc84-b9e6b38f5903}\ShellFolder]
- "Attributes"=dword:a0600000 ;;若要恢复,改为:"Attributes"=dword:20000000
- [HKEY_LOCAL_MACHINE\pe_soft\Classes\WOW6432Node\CLSID\{f874310e-b6b7-47dc-bc84-b9e6b38f5903}\ShellFolder]
- "Attributes"=dword:a0600000 ;;若要恢复,改为:"Attributes"=dword:20000000
复制代码 特别提醒:上述代码可以隐藏“主文件夹”,但同时会带来下图中的后果:资源管理器中,文件(夹)排序如果文件多的话就不正常:如果按名称排序,会连同文件、文件夹一起排序,而正常的是文件夹与文件分开排序的,如下图1所示;文件少的话,就正常,如图2所示。 ★★让资源管理器左侧变成如下图所示: 这是本人的喜好。要导入两个注册码:(当然,其它的项目也要隐藏。) - <font size="1">Windows Registry Editor Version 5.00
- ;;让资源管理器打开时就直接展开所有项目。
- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\NavPane]
- "ExpandedState"=hex:04,00,00,00,16,00,14,00,1f,60,98,3f,fb,b4,ea,c1,8d,42,a7,\
- 8a,d1,f5,65,9c,ba,93,00,00,01,00,00,00,4d,00,00,00,1c,00,00,00,31,53,50,53,\
- a6,6a,63,28,3d,95,d2,11,b5,d6,00,c0,4f,d9,18,d0,00,00,00,00,2d,00,00,00,31,\
- 53,50,53,35,7e,c7,77,e3,1b,50,43,a4,8c,75,63,d7,27,77,6d,11,00,00,00,02,00,\
- 00,00,00,0b,00,00,00,ff,ff,00,00,00,00,00,00,00,00,00,00,54,00,52,00,35,00,\
- 00,00,00,00,52,53,78,12,30,00,f4,66,1a,59,6f,8f,f6,4e,00,00,3a,00,09,00,04,\
- 00,ef,be,52,53,78,12,52,53,79,12,2e,00,00,00,a1,15,00,00,1f,fb,0f,fb,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,09,10,28,00,f4,66,1a,59,6f,8f,f6,4e,00,\
- 00,18,00,00,00,01,00,00,00,4d,00,00,00,1c,00,00,00,31,53,50,53,a6,6a,63,28,\
- 3d,95,d2,11,b5,d6,00,c0,4f,d9,18,d0,00,00,00,00,2d,00,00,00,31,53,50,53,35,\
- 7e,c7,77,e3,1b,50,43,a4,8c,75,63,d7,27,77,6d,11,00,00,00,02,00,00,00,00,0b,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,16,00,14,00,1f,78,40,f0,5f,64,\
- 81,50,1b,10,9f,08,00,aa,00,2f,95,4e,00,00,01,00,00,00,4d,00,00,00,1c,00,00,\
- 00,31,53,50,53,a6,6a,63,28,3d,95,d2,11,b5,d6,00,c0,4f,d9,18,d0,00,00,00,00,\
- 2d,00,00,00,31,53,50,53,35,7e,c7,77,e3,1b,50,43,a4,8c,75,63,d7,27,77,6d,11,\
- 00,00,00,02,00,00,00,00,0b,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,16,\
- 00,14,00,1f,50,e0,4f,d0,20,ea,3a,69,10,a2,d8,08,00,2b,30,30,9d,00,00,01,00,\
- 00,00,4d,00,00,00,1c,00,00,00,31,53,50,53,a6,6a,63,28,3d,95,d2,11,b5,d6,00,\
- c0,4f,d9,18,d0,00,00,00,00,2d,00,00,00,31,53,50,53,35,7e,c7,77,e3,1b,50,43,\
- a4,8c,75,63,d7,27,77,6d,11,00,00,00,02,00,00,00,00,0b,00,00,00,ff,ff,00,00,\
- 00,00,00,00,00,00,00,00
- ;资源管理器左侧栏显示所有文件夹,但不展开每个文件夹!
- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
- "NavPaneShowAllFolders"=dword:00000001
- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
- "NavPaneExpandToCurrentFolder"=dword:00000000</font>
复制代码资源管理器的其它注册代码将在附件中展示,有需要的下载下面的附件或者自己搜索去吧,网上多得是。
资源管理器相关.7z
(168.19 KB, 下载次数: 25)
(11)修改7-Zip的右键菜单,让其理简洁实用。 ★ 打开7-Zip文件夹,再打开7zFM.exe。再选择“选项”,可以对其中相关项目进行修改。在系统中,可以修改与7-Zip关联的文件;在“7-Zip”菜单中的好多项目根本就用不到,把它们去掉。其它的别改。确定后退出。 ★★ 随便找个文件夹,右击并选择7-Zip – 添加到压缩包,在压缩率中选择“极限压缩”,再点击确定。(重启一下资源管理器,即 kill explore) ★★★ 导出7-Zip注册码:打开regedit.exe,找到HKEY_CURRENT_USER\Software\7-Zip 并导出。这个就是你刚才修改的注册码了。离线导入就不说了,只是提醒一下,离线导入时,最好把原来的先删掉,再导入新的。
(12)解决ResourceHacker打开桌面出现白图标的问题
此问题我仅在KURE大神的作品中见到过,并在KURE大神的帮助下解决了此问题,分享一下。我猜可能与删除控制面板的相关项目有关。导入以下注册表即可解决问题。
- Windows Registry Editor Version 5.00
- ;RH打开桌面不显示白图标
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{11016101-E366-4D22-BC06-4ADA335C892B}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{2F6CE85C-F9EE-43CA-90C7-8A9BD53A2467}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{59031a47-3f72-44a7-89c5-5595fe6b30ee}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{64693913-1c21-4f30-a98f-4e52906d3b56}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{89D83576-6BD1-4c86-9454-BEB04E94C819}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{9343812e-1c37-4a49-a12e-4b2d810d956b}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{a00ee528-ebd9-48b8-944a-8942113d46ac}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{daf95313-e44d-46af-be1b-cbacea2c3065}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{e345f35f-9397-435c-8f95-4e922c26259e}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{04731B67-D933-450a-90E6-4ACD2E9408FE}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{11016101-E366-4D22-BC06-4ADA335C892B}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{26EE0668-A00A-44D7-9371-BEB064C98683}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{4336a54d-038b-4685-ab02-99bb52d3fb8b}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{450D8FBA-AD25-11D0-98A8-0800361B1103}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{59031a47-3f72-44a7-89c5-5595fe6b30ee}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{645FF040-5081-101B-9F08-00AA002F954E}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{64693913-1c21-4f30-a98f-4e52906d3b56}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{89D83576-6BD1-4c86-9454-BEB04E94C819}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{9343812e-1c37-4a49-a12e-4b2d810d956b}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{a00ee528-ebd9-48b8-944a-8942113d46ac}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{daf95313-e44d-46af-be1b-cbacea2c3065}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{e345f35f-9397-435c-8f95-4e922c26259e}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{EDC978D6-4D53-4b2f-A265-5805674BE568}]
- [-HKEY_LOCAL_MACHINE\pe_soft\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{f8278c54-a712-415b-b593-b77a2be0dda9}]
- Windows Registry Editor Version 5.00
- ;不显示无名文件夹
- [HKEY_LOCAL_MACHINE\pe_def\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder]
- "Attributes"=dword:00100000
- ;不显示无名文件
- [HKEY_LOCAL_MACHINE\pe_def\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder]
- "Attributes"=dword:00100000
- ;不显示(32位)图标
- [HKEY_LOCAL_MACHINE\pe_def\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder]
- "Attributes"=dword:00100000
复制代码另外,有网友提供下面的注册码,我没试过,不知行不行。 - 隐藏 曾经出现过的 各种莫名其妙的 文件夹
- REGI HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\Attributes=#1048576
- REGI HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\Attributes=#1048576
- REGI HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\Attributes=#1048576
- REGI HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder\Attributes=#2693791748
- REGI HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder\Attributes=#2693791748
- REGI HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{98f275b4-4fff-11e0-89e2-7b86dfd72085}\ShellFolder\Attributes=#2693791748
- REGI HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder\Attributes=#2693791748
- REGI HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{edc978d6-4d53-4b2f-a265-5805674bE568}\ShellFolder\Attributes=#2693791748
- REGI HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder\Attributes=#2693791748
- REGI HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder\Attributes=#2693791748
- REGI HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{f8278c54-a712-415b-b593-b77a2be0dda9}\ShellFolder\Attributes=#2693791748
- REGI HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{bd7a2e7b-21cb-41b2-a086-b309680c6b7e}\ShellFolder\Attributes=#2693791748
- REGI HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{450d8fba-ad25-11d0-98a8-0800361b1103}\ShellFolder\Attributes=#2693791748
复制代码 |